Junglewise Threat Intelligence

sweetalert2 hidden functionality and protestware

Severity: info · Published 2022-11-23

Technologies: sweetalert2 (npm). Vendors: npm.

Executive brief

sweetalert2 is a popular JavaScript library that provides customizable popup alert boxes. Versions 8.19.1 through 11.22.3 contained undisclosed audio and video messages unrelated to the library's core functionality, added by the maintainer. This unexpected behavior could confuse users and damage trust in applications using the library.

Technical details

The vulnerability is classified as hidden/protestware functionality (CWE-912). Between versions 8.19.1 and 11.22.3, the sweetalert2 npm package contained embedded audio and video content that served no purpose related to the library's alert box functionality. This code was injected into the package by the maintainer without disclosure in release notes or documentation. The malicious code executes automatically when the library loads in any application using affected versions. The issue was resolved in version 11.22.4 (released August 2025), which removed the protestware code.

Affected products

  • sweetalert2 sweetalert2 8.19.1 through 11.22.3

Timeline

  • 2022-11-23: disclosed
  • 2025-08-14: patched: Version 11.22.4 removed the protestware functionality

References

Related threats